Impact
A missing authorization check in the Brocade Fabric OS REST API allows any authenticated user to retrieve complete Monitoring and Alerting Policy Suite data across all logical switches. This flaw enables a low‑privilege attacker to dump chassis‑wide system health metrics, port performance violations, and configuration details that should be protected. The vulnerability is a classic missing authorization (CWE‑862).
Affected Systems
Brocade Fabric OS versions earlier than 10.0.1 are affected. The security update addresses the flaw in Fabric OS 10.0.1.
Risk and Exploitability
The CVSS score of 5.1 indicates moderate severity. EPSS information is not available and the issue is not listed in CISA KEV. An authenticated attacker with any role can exploit the exposed endpoint over the network API; no additional access is required. The attack vector is inferred to be remote API access, but the description does not detail further exploitation steps.
OpenCVE Enrichment